Security

Security at Aurakore

Aurakore runs finance, legal, and compliance work for its customers, so this page states plainly what protects that data, what is independently attested today, and what is not yet.

Last updated 5 August 2026

Attestation status
SOC 2 Type II
Audit in progress, target Q1 2027
ISO 27001
Not held
Independent penetration testing
Planned

Certification status

Aurakore does not currently hold a SOC 2 Type II or ISO 27001 certification. A SOC 2 Type II audit is in progress, with certification targeted for Q1 2027. Independent penetration testing is planned as part of the security programme ahead of and following general availability.

We publish this rather than leave it to inference. If a certification is a procurement requirement for you, tell us early and we will be direct about timing.

Protecting data

  • In transitTLS 1.2 or higher for all traffic.
  • At restAES-256 encryption.
  • Access controlRole-based access with least-privilege defaults.
  • Two-factor authenticationTime-based one-time passcodes, set up at first sign-in and required on every account.
  • MonitoringA dedicated security agent layer, described below.

AI safeguards

Aurakore's agents act on live business records, so the controls that matter most are the ones that decide when an agent may act on its own.

  • Human approval gatesConsequential AI-driven actions wait for explicit human approval. No such action completes on its own.
  • Recorded reasoningAgent actions are logged with the inputs they used and the reasoning they produced.

Your data never trains anyone else's model.

Nothing you hold in Aurakore is used to train, fine-tune, or improve a shared model, a foundation model, or any model another customer will touch. This holds in every region, including the United States. There is no setting to switch and no opt-out to find, because there is nothing to opt out of.

  • Your recordsFinancial records, HR data, legal documents, and every other business record you hold in Aurakore are never used to train a shared or foundation model.
  • Prompts and outputsWhat your people ask an agent, and what the agent answers, are not training data.
  • Never pooledYour data is never combined with another customer's for any modelling purpose.
  • Models inside your own workspaceSome features compute a statistical model from your own records to serve you, such as predictive lead scoring in Marketing. It is built in your tenant, applied only to you, and neither its inputs nor its outputs leave it.
  • Downstream model providersThe providers that serve models to Aurakore are contractually prohibited from training on customer data under our enterprise agreements.
  • Platform telemetryAggregated, irreversibly de-identified telemetry is used to monitor platform health. It carries no customer records and is not model training.

Full detail is in the privacy policy.

The security agent layer

Aurakore runs a dedicated security service with six specialised agents. They are separate from the agents that do customer work, and customers do not interact with them.

How the six security agents set platform posture Five operational agents, Watcher, Hunter, Responder, Forensics and Red team, report into a Commander. The Commander sets the platform security posture across four levels and cannot lower it below a floor set by an independent control. FIVE OPERATIONAL AGENTS COMMANDER PLATFORM POSTURE Watcher Anomalies, policy violations Hunter Lateral movement, exfiltration Responder Contain, collect, coordinate Forensics Attack chain, incident report Red team Attacks Aurakore's own agents Commander Reviews the picture the other five produce Level 4 Level 3 Level 2 Level 1 Escalates upward on repeated events Floor set by an independent control The Commander cannot go below it
The five operational agents report into the Commander, which sets the platform security posture. The floor is set outside the Commander, so no single agent can stand the platform down.
  • WatcherReviews security events for anomalies, suspicious patterns, and policy violations, and raises alerts.
  • HunterSearches audit logs for lateral movement, privilege escalation, and data exfiltration.
  • ResponderHandles incidents: contains the threat, collects evidence, coordinates the response.
  • ForensicsAnalyses medium and higher severity incidents, reconstructs the attack chain, and produces the incident report.
  • Red teamAttacks Aurakore's own agents: prompt injection, restricted-advice checks, and attempts to bypass the human approval gates.
  • CommanderReviews the picture the other five produce and sets the platform security posture across four levels, escalating on repeated events and immediately on any cross-tenant event. It cannot lower the posture below the floor set by an independent control.

Adversarial testing on every deployment

A security suite runs against the live agent endpoints as part of each deployment, covering prompt injection, jailbreaks, attempts to bypass human approval, cross-tenant data leakage, and system prompt extraction.

Where data is processed

Customer data is processed in the region chosen at workspace creation, selected for customer location, regulatory requirements, and residency commitments.

Processing regions and the framework each one serves.
Region Framework Status
Iowa, United States Primary Live
Montréal, Canada PIPEDA Live
Toronto, Canada PIPEDA Live
Frankfurt, Germany GDPR Live
Paris, France GDPR Live
Madrid, Spain GDPR Live
London, United Kingdom UK GDPR Live
São Paulo, Brazil LGPD Activating
Dubai, United Arab Emirates UAE PDPL Activating
Doha, Qatar Qatar PDPPL Activating

Transfers out of the EEA, the UK, and other jurisdictions with transfer restrictions rely on Standard Contractual Clauses. The region is fixed after provisioning; contact support to migrate.

Retention

  • Security and audit logs12 months minimum, up to 7 years.
  • Account data after termination90 days minimum, up to 7 years where law or the data processing agreement requires it.

At the end of the applicable period, personal data is securely deleted or anonymised.

Reporting a vulnerability

If you believe you have found a security issue, email us with enough detail to reproduce it. Please do not disclose it publicly until we have had a chance to respond. We will acknowledge your report and keep you informed while we investigate.

security@aurakore.com

The same address handles security questionnaires, diligence requests, and data processing agreements.

A note on limits

No security measure is guaranteed to be impenetrable. In the event of a personal data breach, Aurakore will notify affected parties and regulators as required by applicable law. Nothing on this page is a warranty; contractual commitments are set out in your agreement and data processing agreement.